# Can't implement custom pattern inside a filter

**URL:** <https://discuss.elastic.co/t/cant-implement-custom-pattern-inside-a-filter/84402>\
**Category:** Logstash\
**Created:** [May 3, 2017, 11:18am UTC](https://discuss.elastic.co/t/cant-implement-custom-pattern-inside-a-filter/84402 "2017-05-03T11:18:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Darya\_Semenova](https://avatars.discourse-cdn.com/v4/letter/d/7ba0ec/32.png) [@Darya\_Semenova](https://discuss.elastic.co/u/Darya_Semenova)\
**Post date:** [May 3, 2017, 11:18am UTC](https://discuss.elastic.co/t/cant-implement-custom-pattern-inside-a-filter/84402/1 "2017-05-03T11:18:52Z")

</div>

Hello,  
For some reason in my case logstash keeps not compling when I try to use a custom pattern. So I tried to implement a needed pattern as a field (the easier one now for testing, just a letter with a '-' in front of it), but it doesn't seem to work. Logstash compiles, but logs do not match.

```
grok {
    remove_tag => ["_grokparsefailure"]
    match => {
        "message" => ["%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: xCAT: Allowing %{GREEDYDATA:xCAT_comm_exec} (?<o_option> (\-[O-Oo-o])) %{GREEDYDATA:x_CAT_used_nodes} for %{USERNAME:xcat_user} from %{SYSLOGHOST:xcat_user_hostname}"]
     }
    add_field => ["received_at", "%{@timestamp}"]
    add_field => ["received_from", "%{host}"] }
}

```

Logs that are supposed to be parsed with that grok filter look like this:

```
May 11 12:14:42 head-testing xcat[12345]: xCAT: Allowing lsdef -t node -o n00p123,n01p123,n10p123,n01p123,ndfl-mic1,testnode1 for admin from localhost
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 3, 2017, 11:24am UTC](https://discuss.elastic.co/t/cant-implement-custom-pattern-inside-a-filter/84402/2 "2017-05-03T11:24:17Z")

</div>

> For some reason in my case logstash keeps not compling when I try to use a custom pattern.

What's the error message?

> So I tried to implement a needed pattern as a field, but it doesn't seem to work.

I don't understand what "implement a pattern as a feild" means.

---

<div class="post-metadata">

**Author:** ![Darya\_Semenova](https://avatars.discourse-cdn.com/v4/letter/d/7ba0ec/32.png) [@Darya\_Semenova](https://discuss.elastic.co/u/Darya_Semenova)\
**Post date:** [May 3, 2017, 11:26am UTC](https://discuss.elastic.co/t/cant-implement-custom-pattern-inside-a-filter/84402/3 "2017-05-03T11:26:45Z")

</div>

> [@magnusbaeck](#):
>
> I don't understand what "implement a pattern as a feild" means.

This part in the command:

```
(?<o_option> (\-[O-Oo-o])) 

```

This part is supposed to find -o in

```
May 11 12:14:42 head-testing xcat[12345]: xCAT: Allowing lsdef -t node -o n00p123,n01p123,n10p123,n01p123,ndfl-mic1,testnode1 for admin from localhost

```

---

<div class="post-metadata">

**Author:** ![Nico-DF](https://avatars.discourse-cdn.com/v4/letter/n/ed8c4c/32.png) [@Nico-DF](https://discuss.elastic.co/u/Nico-DF)\
**Post date:** [May 3, 2017, 11:37am UTC](https://discuss.elastic.co/t/cant-implement-custom-pattern-inside-a-filter/84402/4 "2017-05-03T11:37:40Z")

</div>

> [@Darya\_Semenova](#):
>
> (?\<o\_option\> (-[O-Oo-o]))

You're currently matching something like: `[Space]-o` (watch out for spaces!)

Try `(?<o_option>\-[Oo])` instead  
Always test your grok pattern before (here for exemple [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/))  
And when having a problem, use the rubydebug output codec to see any stacktrace

---

<div class="post-metadata">

**Author:** ![Darya\_Semenova](https://avatars.discourse-cdn.com/v4/letter/d/7ba0ec/32.png) [@Darya\_Semenova](https://discuss.elastic.co/u/Darya_Semenova)\
**Post date:** [May 3, 2017, 11:39am UTC](https://discuss.elastic.co/t/cant-implement-custom-pattern-inside-a-filter/84402/5 "2017-05-03T11:39:26Z")

</div>

Ok, thank you very much for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2017, 11:46am UTC](https://discuss.elastic.co/t/cant-implement-custom-pattern-inside-a-filter/84402/6 "2017-05-31T11:46:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
